Security at Let's Get Coffee
How we protect member data, with an honest account of what's in place today and what's still on the roadmap.
Last updated June 17, 2026
Our approach
Let's Get Coffee handles something personal: who people are, what they care about, and who they'd like to meet. We treat that seriously. We're an early-stage company, and we'd rather tell you plainly what we do today than imply guarantees we haven't earned.
Encryption
All traffic between you and Let's Get Coffee is encrypted in transit with HTTPS/TLS. Your data is stored in a managed database with encryption at rest provided by our infrastructure.
Hosting and infrastructure
We build on Supabase for our database, authentication, and file storage, running on established cloud infrastructure with the operational and physical security those providers maintain. We don't run our own servers in a closet.
Access controls
Data is scoped to the organization it belongs to, enforced at the database level with row-level security. Profile visibility is deny-by-default: information is shared only where it's meant to be, and internal access follows least-privilege principles.
Sign-in
We use passwordless sign-in: a one-time code sent to your email, or single sign-on with Google, Microsoft, or Slack. There's no password to reuse, guess, or leak. Calendar connections use OAuth with the narrowest scope needed, and you can revoke that access at any time.
Your data, your control
Privacy-protective defaults are part of the security story:
- Participation is opt-in, and you control what your profile shares.
- Profile photos are recognition-only: image metadata (EXIF) is stripped on upload, and a photo is never used as a matching signal or shown on the choose-to-meet screen.
- Connected calendars are read for availability only, never the contents of your events, and access is revocable.
- You can edit or delete your information, and request account deletion, at any time.
Enterprise controls
For Corporate plans we offer additional controls for larger organizations: SSO & SAML, HRIS provisioning, and audit logs & reporting. If your organization has specific security or compliance requirements, talk to us at hello@letsgetcoffee.app and we'll walk through what we can support.
Certifications and roadmap
We're being upfront: formal certifications such as SOC 2 are not yet in place. They're on our roadmap as we grow, and we'll update this page as that work lands. In the meantime, we're glad to answer specific questions about our practices.
Responsible disclosure
If you believe you've found a security vulnerability, we want to hear from you. Email hello@letsgetcoffee.app with "Security" in the subject line and enough detail to reproduce the issue. Please give us a reasonable chance to investigate and fix it before disclosing publicly. We're grateful to researchers who help keep our members safe.
Questions about this page? Email hello@letsgetcoffee.app.
Back to home